DENTARA

PRIVACY POLICY

Version 1.5Effective date: 21 September 2026

Contents

1. About this Privacy Policy

This Privacy Policy explains how personal data are collected, used, shared, retained and protected in connection with the DENTARA platform, and what rights the persons concerned have. It applies to the website and administration interface at dentarai.com, to the client applications and the application programming interface through which the Platform is made available, and to the communications, support, marketing and training activities connected with it.

Capitalised terms used here have the meaning given to them in the Platform Terms and Conditions for the Platform (the “Terms”).

Two different roles. This Privacy Policy describes the processing for which the Digital Trader and the Technology Provider decide the purposes and means, that is, the processing in which they act as controllers. It concerns in particular the personal data of the representatives and Authorised Users of customer practices, of prospective customers, of visitors to the website, of participants in training, and of persons who contact us.

Patient data. Personal data relating to the patients of a dental practice which uses the Platform are processed on the instructions of that practice. The practice is the controller of those data; the Technology Provider is its processor and processes them only as described in the Data Processing Agreement in Annex 1 to the Terms. Patients who wish to know how their data are used, or who wish to exercise their rights, should contact the dental practice which treats them and consult that practice’s own privacy notice. Section 6 of this Privacy Policy describes that role in more detail.

Personal data are processed in accordance with Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data of the United Arab Emirates and, where it applies, Regulation (EU) 2016/679 (the General Data Protection Regulation) and other mandatory data-protection legislation of the country concerned.

2. Who is responsible for your data

Two companies are involved, each in its own role under the Terms:

  • DENTARA STRATEGIES - FZCO, a free zone company incorporated under the regulations of the Dubai Integrated Economic Zones Authority, licence number 74464, registered at IFZA Business Park, Building A1, Dubai Digital Park, Dubai Silicon Oasis, PO Box 342001, Dubai, United Arab Emirates (the “Digital Trader”), is the company with which dental practices contract. It is the controller of account, order, transaction and billing data, of support and complaint correspondence, and of marketing data. Contact: dentaraisupport@gmail.com.
  • Rahadu – F.Z.C, a free zone company incorporated under the Ajman Free Zone regulations, licence and registration number 36978, registered at Ajman Free Zone C1 Building, Ajman, United Arab Emirates (the “Technology Provider”), owns and operates the core platform on which DENTARA runs, and operates its credit and settlement system. It is the controller of the technical, security and product-usage data which it processes to operate, secure and improve the platform, and the processor of the data which it processes on behalf of dental practices. Contact: dentarai@dentarai.com.

Requests addressed to dentaraisupport@gmail.com and dentarai@dentarai.com are routed to the entity responsible for the processing concerned. Where a different entity assumes one of these roles, customers are notified in accordance with Article 27 of the Terms and this Privacy Policy is updated accordingly.

Data Protection Officer appointed under Federal Decree-Law No. 45 of 2021: Morin Wambui Muriuki, contact: dentarai@dentarai.com. Representative in the European Union appointed under Article 27 of the General Data Protection Regulation: Martin Ivanco.

3. What data we collect and how

We collect the following categories of personal data, depending on the relationship concerned. The data are provided by the person concerned or by the customer practice which employs or engages them, or are generated when the Platform or the website is used. We do not buy personal data from data brokers.

  • Account and user data: name, professional role, business electronic-mail address and telephone number, employer, tenant and user identifiers, assigned role and permissions, authentication data including multi-factor authentication settings, language and interface preferences.
  • Order, transaction and billing data: the identity of the customer practice and of the persons who act for it, trade licence and professional registration details, tax identifiers such as a Tax Registration Number or value added tax identification number, address of establishment, orders, plans, invoices, payments, credit notes, the record of Credit purchases and the Credit Book, and the records which we are required to keep to establish the place of supply and the correct tax treatment.
  • Usage, product and technical data: records of actions taken in the Platform, log and session records, device, browser and operating-system information, internet protocol address and the approximate country derived from it, performance and error telemetry, and security events.
  • Support and complaint data: the content of tickets, messages and calls with our support and complaint channels, and the records of the resolution.
  • Marketing and prospect data: business contact details, the organisation concerned, interests expressed, event and webinar registrations, and the record of consents and objections.
  • Training and certification data for Module 4A: identity, professional registration where a course requires it, enrolment, attendance, assessment results and certificates, and, for in-person workshops in the United Arab Emirates, the information necessary for registration, access to the venue and safety.
  • Patient account and purchase data: where a patient purchases Credits directly under the Patient Terms, the patient’s name and electronic-mail address, account and wallet identifiers, purchases, payments, invoices, Credit balance and expiry, referral and cashback records, and support correspondence. The Digital Trader is the controller of these data. They do not include the patient’s health or treatment data, which remain under the control of the dental practice.
  • Device data: where a practice takes a Device, the identifiers, location, configuration, firmware version, status and service records of that Device, and the technical records of the captures it performs. Images captured through a Device are patient data and are processed on behalf of the practice.
  • Website data: the data collected through cookies and similar technologies, as described in Section 12.

We do not collect payment-card details. Card payments are processed by our payment service provider, which receives the payment data directly.

Providing business contact details and account data is necessary in order to create and operate a Tenant and to give an Authorised User access. Providing the order, tax and licensing information is necessary in order to conclude and perform the contract and to comply with our tax and regulatory obligations. Where information is optional, that is indicated when it is requested.

We use the data described in Section 3 for the following purposes:

  • To conclude and perform the contract with the customer practice, to activate and operate its Tenant, to give Authorised Users access and to deliver the Modules ordered — legal basis: the performance of a contract, or our legitimate interest in performing the contract with the organisation which the person represents.
  • To verify the eligibility, licensing status and professional standing of a customer practice, as Article 3 of the Terms requires — legal basis: compliance with a legal obligation and our legitimate interest in contracting only with duly licensed professional customers.
  • To process orders, meter consumption, issue invoices, receipts and credit notes, collect payment and handle refunds — legal basis: the performance of a contract and compliance with a legal obligation.
  • To determine the country in which the Platform is used, from the customer’s billing details and, where we collect it, the internet protocol address, in order to apply the correct Value Added Tax or equivalent tax treatment and to retain evidence of it — legal basis: compliance with a legal obligation.
  • To provide support, to investigate incidents and to handle complaints — legal basis: the performance of a contract and our legitimate interest in supporting our customers.
  • To operate, monitor, secure and troubleshoot the Platform, to prevent, detect and investigate fraud, abuse and security incidents, and to enforce the Terms — legal basis: our legitimate interest in a secure and correctly functioning service, and compliance with a legal obligation.
  • To analyse the use of the Platform and of the website, to measure performance and to improve and develop the Platform and our other products and services — legal basis: our legitimate interest in improving our services and, where required, consent.
  • To send marketing communications about our own products, services, events and training to business contacts, from which the recipient may opt out at any time — legal basis: our legitimate interest in direct marketing to business contacts or, where required by the law applicable to the recipient, consent.
  • To deliver training and to issue certificates under Module 4A, and to organise workshops — legal basis: the performance of a contract and our legitimate interest in administering our training activities.
  • To comply with legal obligations, including tax, accounting, record-keeping, sanctions-screening and regulatory obligations, and to establish, exercise or defend legal claims — legal basis: compliance with a legal obligation and our legitimate interest in defending our rights.

Where we rely on a legitimate interest, we have assessed that interest against the rights and freedoms of the persons concerned, and the person concerned may object to that processing as described in Section 9.

We may also use data which have been irreversibly anonymised and aggregated, so that they no longer relate to an identified or identifiable person, in order to operate, secure, measure, benchmark, improve and develop the Platform and for statistical purposes. Anonymised data are no longer personal data.

5. Artificial intelligence and the training of models

The Platform uses artificial-intelligence functionality to generate analyses, proposals, drafts, transcripts, conversational responses and educational content. Those outputs are informational and support the professional judgement of a qualified clinician, as Article 8 of the Terms sets out in detail.

Personal data which we process on behalf of a customer practice, including data relating to its patients, are not used to train, fine-tune, evaluate or improve artificial-intelligence models, and are not made available to any model provider for that purpose, unless the practice has given a separate, specific and revocable written opt-in under the Data Processing Agreement. We contract with our model providers on terms which exclude the use of our customers’ inputs and outputs for the providers’ own training purposes.

Personal data which we process as controllers, in particular account, usage and support data, are used to operate, secure and improve the Platform. They are not used to make decisions about a person which produce legal effects concerning that person or which similarly significantly affect them, and no solely automated decision-making of that kind takes place.

6. Data of patients: our role as processor

When a dental practice uses the Platform to process data relating to its patients, including intraoral scans, radiographs, clinical notes, appointment and contact data, voice recordings and transcripts, education records and consent records, that practice determines the purposes and the means of the processing and is the controller. The Technology Provider processes those data only on the practice’s documented instructions and for the purpose of providing the Modules which the practice has ordered, and of securing and supporting the Platform.

Two different sets of data about a patient. A patient’s health and treatment data, and everything the patient does inside the practice’s Virtual Practice, are controlled by that practice and processed by the Technology Provider on its instructions. Separately, where a patient buys Credits in their own name, the account and purchase data for that transaction are controlled by the Digital Trader, which is the seller. The Digital Trader does not receive the patient’s health or treatment data, and the practice does not receive the patient’s payment data.

The Technology Provider is the processor of those data, as the operator of the platform. The Digital Trader does not access patient data in the ordinary course; where access is necessary in order to provide support or to resolve an incident, the Digital Trader acts as a sub-processor engaged by the Technology Provider and is bound by the same obligations. The terms of that processing, including the security measures, the use of sub-processors, international transfers, the handling of personal data breaches, assistance with the rights of patients, and the return and deletion of data, are set out in the Data Processing Agreement in Annex 1 to the Terms.

A patient who wishes to obtain information about the processing of their data, or to exercise a right of access, correction, deletion, portability, restriction or objection, or to withdraw a consent, should contact the dental practice which treats them. Where we receive such a request directly, we refer the person to the practice concerned and, unless the practice instructs us otherwise, we do not respond to the request on the merits. We assist the practice in responding within the period which the law allows it.

7. Who we share your data with

We do not sell personal data and we do not make personal data available to third parties for those parties’ own purposes. We share personal data only with the following categories of recipients:

  • Between the Digital Trader and the Technology Provider, to the extent each of them needs the data for the purposes described in this Privacy Policy.
  • Providers of cloud infrastructure and hosting, which store and process the data on our behalf.
  • Providers of artificial-intelligence and machine-learning services used by the Modules, engaged on terms which exclude the use of the data for the providers’ own training purposes.
  • Providers of electronic mail, messaging, telephony, support and ticketing tools, and of product telemetry and security monitoring.
  • The payment service provider, for the processing of payments, and, where applicable, providers of credit assessment and debt collection.
  • Where a customer practice so configures the Platform, the providers of integrations with that practice’s own systems, which act on the practice’s instructions.
  • Partners, resellers and referral partners, which receive only the information needed to administer the relationship and to calculate their remuneration.
  • Professional advisers, auditors, insurers and, where we are legally required to do so, competent authorities and courts.
  • A purchaser or successor in the event of a reorganisation, merger, acquisition or transfer of all or part of our business, subject to the same protections continuing to apply.

Recipients which process personal data on our behalf act on our documented instructions under a written data-processing agreement or an equivalent legal obligation, and are required to provide a level of protection equal to that described in this Privacy Policy. The current list of the processors and sub-processors used for the Platform is published at dentarai.com/subprocessors and is available on request at dentarai@dentarai.com.

8. International transfers

We are established in the United Arab Emirates, and some of our processors are established in the European Economic Area, in the United Kingdom, in the United States and in other countries. Personal data may therefore be transferred outside the country in which the person concerned lives or in which the customer practice is established.

Where personal data are transferred to a country which does not provide an adequate level of protection under Federal Decree-Law No. 45 of 2021, the transfer takes place on the basis of appropriate safeguards or of a derogation permitted by that law. Where the General Data Protection Regulation applies, transfers out of the European Economic Area take place on the basis of the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, supplemented where necessary by additional technical and organisational measures, or on the basis of another lawful transfer mechanism. A copy of the safeguards applied may be requested at dentarai@dentarai.com.

Where an Order provides for a specific hosting region or data-residency option, that option is maintained for the subscription term, as Article 16 of the Terms provides.

9. Your rights

Subject to the conditions of the law applicable to you, you have the right to: obtain confirmation of whether we process your personal data and access to those data; have inaccurate data corrected; have your data deleted; obtain a copy of the data you provided in a structured, commonly used and machine-readable format and have them transferred to another controller; restrict or object to certain processing, including processing based on a legitimate interest and processing for direct marketing; withdraw a consent you have given, without affecting the lawfulness of processing carried out before the withdrawal; and not be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you.

You may exercise these rights by writing to dentarai@dentarai.com, or, for account, order and billing matters, to dentaraisupport@gmail.com. We may ask for the information needed to verify your identity and the scope of your request. We answer within the period required by the applicable law and at the latest within one month, and we inform you if that period needs to be extended.

Where your request concerns data which we process on behalf of a dental practice, we refer you to that practice, as described in Section 6.

You also have the right to lodge a complaint with the United Arab Emirates Data Office or, where the General Data Protection Regulation applies to you, with the supervisory authority of your country of residence or place of work.

10. How long we keep your data

  • Account and user data: for the duration of the customer relationship and of the user’s authorisation, and deleted or anonymised within ninety (90) days after the account is closed or the authorisation is withdrawn.
  • Data processed on behalf of a customer practice, including patient data: for the periods set out in the Data Processing Agreement, that is, for the subscription term, followed by a retrieval period of thirty (30) days and deletion within a further thirty (30) days, subject to any longer retention required by law.
  • Order, transaction, invoicing and tax records, including the records evidencing the place of supply: for the retention periods required by the applicable tax and accounting legislation, currently seven years in the United Arab Emirates and up to ten years where required in respect of supplies to customers in the European Union. These records are kept even after the account is closed and are not used for any other purpose.
  • Support and complaint correspondence: for three (3) years after the matter is closed, or for the duration of the applicable limitation period where a claim is possible.
  • Security, audit and access logs: for twelve (12) months, or longer where necessary to investigate an incident or where required by law.
  • Marketing data and records of consents and objections: until the objection or the withdrawal of consent and, in respect of the record of that objection or withdrawal, for as long as necessary to demonstrate that we have respected it.
  • Training, attendance and certification records for Module 4A: for the period required to evidence the certificate issued and, where a course is accredited, for the period required by the accrediting body.

Data which have been irreversibly anonymised may be kept without a time limit, as they no longer identify anyone.

11. Security

We apply technical and organisational measures appropriate to the risk, including encryption of personal data in transit and at rest, identity and access management with least-privilege and multi-factor authentication, logical isolation of each customer tenant, logging and monitoring, vulnerability management and independent penetration testing, secure development practices, backup and tested recovery procedures, and vetting and training of personnel. Those measures are described in detail in Appendix 2 to the Data Processing Agreement.

Access by our personnel to data held in a customer tenant is limited to what is necessary to deliver support or to resolve an incident, and is logged.

If a personal data breach occurs which is likely to result in a risk to the rights of the persons concerned, we notify the competent authority and, where required, those persons, in accordance with the applicable law. Where the breach concerns data processed on behalf of a customer practice, we notify that practice within the period set out in the Data Processing Agreement.

12. Cookies and similar technologies

The website and the administration interface use cookies and similar technologies. Strictly necessary cookies are used for the website and the interface to work, to keep a user signed in, to remember choices and to keep the service secure; they do not require consent. Other cookies and similar technologies, for example for analytics, for measuring the performance of the website and for attributing referrals from partners, are used only where permitted by the law applicable to the visitor and, where required, with the visitor’s consent, which may be given and withdrawn at any time in the cookie settings on the website. An up-to-date list of the cookies and similar technologies we use, and of the third parties that provide them, is maintained at dentarai.com/cookies.

13. Children

Accounts on the Platform are created only for persons aged 18 years or older who act in a professional capacity. We do not knowingly create accounts for, or collect account data of, persons under 18.

Data relating to patients who are minors may be processed through the Platform on the instructions of a dental practice, within its own clinical relationship and under its responsibility as controller, including in respect of the consent or authorisation of a parent or legal guardian. We process such data only as that practice instructs, and do not use them for any purpose of our own.

14. Changes to this Privacy Policy

We may update this Privacy Policy, in particular where the Platform, our processors or the applicable law change. Where a change materially affects the persons concerned, we inform them in advance through the Platform or by electronic mail. The current version is always published on the website, together with its effective date.

15. How to contact us

Digital Trader: DENTARA STRATEGIES - FZCO, IFZA Business Park, Building A1, Dubai Digital Park, Dubai Silicon Oasis, PO Box 342001, Dubai, United Arab Emirates, licence number 74464, electronic mail dentaraisupport@gmail.com.

Technology Provider: Rahadu – F.Z.C, Ajman Free Zone C1 Building, Ajman, United Arab Emirates, licence and registration number 36978, electronic mail rahadu@rahadu.ae. Data-protection requests may be addressed to dentarai@dentarai.com.

Data Protection Officer: Morin Wambui Muriuki, dentarai@dentarai.com.

Representative in the European Union appointed under Article 27 of the General Data Protection Regulation: Martin Ivanco.